DPDP penalties in India. Up to ₹250 crore per violation.
The Digital Personal Data Protection Act, 2023 sets financial penalties for data-protection failures through the Schedule read with Section 33. Ceilings run from ₹10,000 for data-principal misuse up to ₹250 crore for security-safeguards failure, with two ₹200 crore bands for breach-notification and children-data obligations, and a ₹150 crore band for Significant Data Fiduciary obligations. The Data Protection Board of India adjudicates each case after inquiry and can weigh mitigation. This page breaks down every band with the exact section citation, and the controls the DPB will ask for.
The seven penalty bands under DPDP Act 2023
The DPDP Schedule assigns each type of non-compliance a maximum penalty. The Data Protection Board of India (DPB) adjudicates the actual number under Section 33, weighing gravity, duration and mitigation. Here is what each band covers.
Security safeguards failure
Failure to take reasonable security safeguards to prevent a personal data breach under Section 8(5). The single largest exposure. Applies to encryption, access control, hardening, logging, backup, incident response.
Breach notification failure
Failure to give the Data Protection Board or affected data principals notice of a personal data breach. Time-of-essence obligation, hospitals, fintechs, e-commerce especially exposed.
Children data breach
Failure to fulfil Section 9 obligations for children: verifiable parental consent, prohibition on tracking, prohibition on targeted advertising, prohibition on processing that causes detrimental effect.
SDF additional obligations
Significant Data Fiduciaries failing to appoint a DPO based in India, or to conduct DPIAs and independent audits under Section 10. Applies to most banks, NBFCs, insurance, large healthcare, and platform businesses.
Voluntary undertaking breach
Breach of a voluntary undertaking accepted by the DPB under Section 32. Under Schedule Item 6, the penalty extends to the amount applicable to the underlying contravention. So if the underlying breach carried a ₹250 Cr ceiling, breaking the undertaking exposes you to the same ₹250 Cr ceiling.
Other DPDP obligations
Catch-all for other failures, consent format, purpose limitation, retention, cross-border transfer, DSR fulfilment, notice requirements. Any obligation not called out specifically lands here.
Data principal misuse
A data principal filing false or frivolous grievances, or misusing rights (Section 15). Small by design, the DPDP focuses accountability on fiduciaries.
Which section triggers which fine
The Schedule to the DPDP Act 2023 sets the ceiling. The DPB decides the actual figure after inquiry.
| Provision breached | Nature of default | Max penalty |
|---|---|---|
| Section 8(5) | Failure to take reasonable security safeguards to prevent a personal data breach | ₹250 Cr |
| Section 8(6) & DPDP Rules 2025 Rule 7 | Failure to notify DPB and affected data principals of a personal data breach | ₹200 Cr |
| Section 9 | Failure to fulfil additional obligations in relation to children, verifiable parental consent, no tracking, no targeted ads | ₹200 Cr |
| Section 10 | Failure of Significant Data Fiduciary to fulfil DPO, DPIA and audit obligations | ₹150 Cr |
| Section 32 (Schedule Item 6) | Breach of a voluntary undertaking accepted by the DPB. Penalty extends to the amount applicable to the underlying contravention. | Variable |
| Any other provision | Any other breach of the DPDP Act or Rules, consent, purpose, retention, cross-border, DSR | ₹50 Cr |
| Section 15 | Data principal furnishing false particulars, filing frivolous grievances, or misusing rights | ₹10,000 |
Six factors the DPB weighs before setting the fine
The DPB is not required to impose the maximum. Under Section 33(2) it must consider these mitigating and aggravating factors.
Nature and gravity of breach
How intentional or negligent was the failure. A one-off configuration error is weighed differently to a policy of ignoring data-principal rights.
Duration of breach
How long the violation continued. Six months of missing consent is weighed harder than a two-day lapse.
Impact on data principals
Number of individuals affected, category of data, whether the data was sensitive, whether harm was actually caused.
Financial gain from breach
Whether the fiduciary derived commercial benefit from the non-compliance, e.g., unlawful profiling or targeted ads.
Repetitive or recurring
A first offence weighs less than repeated failures across the same business.
Mitigation actions taken
Prompt breach notification, remediation, cooperation with DPB, prior compliance programme. This is where an audit-ready compliance stack pays off.
Who bears the biggest DPDP penalty risk
Hospitals & diagnostic labs
Sensitive health data at volume. Section 8(5) + Section 10 (SDF likely) + Section 9 (paediatric consent). Combined exposure per incident: ₹600 Cr+.
See industry doorNBFCs & fintechs
RBI overlap + KYC + Aadhaar. Section 8(5) + Section 10 (SDF certain) + cross-border transfer. Combined exposure: ₹400 Cr+.
See industry doorHotels & hospitality
Guest ID, payment data, CCTV, WiFi logs. Section 8(5) + breach notification failure + OTA data sharing without DPA.
See industry doorE-commerce & marketplaces
Buyer PII + seller PII + payment tokens + targeting cookies. Consent failure + retention creep + cross-border transfer to global CDN.
See industry doorSaaS & B2B tech
Processor role + international transfers + audit-readiness. Vendor DPA failure + SDF classification if scale is large.
See industry doorEdTech & schools
Under-18 users almost universally. Section 9 exposure of ₹200 Cr on tracking or targeted ads alone.
See industry doorThe eight controls the DPB will ask you to prove
Section 33(2)(f) rewards documented mitigation. Every one of these has a dcomply module.
Consent artefacts
Free, informed, specific, unambiguous, withdrawable. Versioned, timestamped, exportable.
See moduleRecord of Processing Activities (RoPA)
Every purpose, every category, every retention rule. The first thing the DPB will ask for.
See moduleDSR fulfilment log
Every access, correction and erasure request with SLA clock. Section 12 evidence.
See moduleBreach notification workflow
DPB format + affected data principal notice. 72-hour ready. Section 8(6).
See moduleDPIA library
Section 10(2)(c) obligation for SDFs. dcomply auto-triggers on high-risk processing.
See moduleIndependent audit trail
Section 10(2)(c) audit obligation. Evidence Locker keeps every artefact hash-chained.
See moduleThe exact questions general counsel asks about DPDP fines.
Don't wait for the DPB to knock.
Get a free 5-minute DPDP readiness score. Know exactly which of the seven penalty bands you're exposed to today.